NSE4 Security Profiles Practice Question
A mid-sized company has a FortiGate 100F running FortiOS 7.2. They have two internal networks: Trusted (10.1.1.0/24) for employees and Guest (10.2.2.0/24) for visitors. The Guest network has a firewall policy that allows internet access only, with an application control profile that blocks all peer-to-peer and gaming applications. Recently, users on the Guest network have been able to play online games (e.g., Fortnite) despite the block. The administrator checks the application control profile and confirms that 'Fortnite' is listed as blocked. There are no other policies allowing Guest traffic. The administrator also notices that the Guest policy has 'set utm-status enable' and the application control profile is applied. What is the most likely reason that Fortnite is not being blocked?
⚠ Common exam trap
A common mix-up: candidates assume SSL inspection is mandatory for blocking encrypted applications, but the real issue is that outdated signatures fail to recognize the latest application variants, even when the profile is correctly applied and UTM is enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application control signatures are outdated and do not include the latest Fortnite signatures.
If the Application Control signatures are outdated, the FortiGate may not recognize the latest Fortnite traffic patterns or encrypted handshakes, allowing the game to bypass the block. Even though the policy has UTM enabled and the profile is applied, stale signatures cannot match new application variants or updates. Regularly updating the IPS/Application Control database via FortiGuard is essential to maintain effective blocking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall policy is missing 'set deep-inspection enable' for application control to work.
Why it's wrong here
Application control on FortiGate is activated by assigning an application control profile (application-list) to a firewall policy; there is no 'set deep-inspection enable' command on a policy. Deep inspection is a separate SSL/SSH profile used to decrypt encrypted traffic, and it is not a prerequisite for application identification. FortiGate's application control engine uses IP/port, protocol decoders, and TLS SNI/host metadata to detect many applications even without decryption. Without deep inspection, only visibility into encrypted payloads is reduced, not the entire application control function.
- ✗
SSL inspection is required to block encrypted game traffic, and it is not enabled.
Why it's wrong here
SSL inspection is not mandatory for blocking games like Fortnite because FortiGate application control can identify the game's traffic using IP/port ranges, TLS Server Name Indication (SNI), and cached host information. Enabling deep inspection (an SSL/SSH profile) would allow payload-level signature matching, but the initial identification can already happen at the handshake and connection level. If the signature database is current, Fortnite can be blocked even without decryption. Therefore, the absence of SSL inspection is not the root cause in this scenario.
- ✗
The application control profile is not applied to the correct policy.
Why it's wrong here
The scenario explicitly states that the application control profile is applied to the Guest policy, so a policy-applied error is not the issue. While a misapplied profile would indeed prevent blocking, the problem here cannot be the policy assignment since that condition is already satisfied. Troubleshooting would confirm that the correct 'application-list' is bound to the policy and that the Guest traffic matches that policy before considering other causes. In this case, the applied profile is correct, so the cause must lie in the profile's signature database.
- ✓
The application control signatures are outdated and do not include the latest Fortnite signatures.
Why this is correct
Newer game traffic, such as Fortnite, uses frequently changing update servers and protocols, so a FortiGate with an outdated FortiGuard signature database will fail to match those flows. Application control relies on regularly updated signatures to identify application-specific traffic patterns and unblocked domains. If the signature version predates a major Fortnite update, the traffic is passed as unknown. The solution is to update the FortiGuard application control signatures (either manually or via scheduled updates) and then retest the Guest policy.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.